Skip to content

Generate TLS certificates from TLSA DNS records that are safe to add to a root CA trust store

License

Notifications You must be signed in to change notification settings

namecoin/safetlsa

Repository files navigation

safetlsa

safetlsa is a library that generates TLS certificates from TLSA records that are safe to use as trust anchors. It uses name constraints and dehydrated certificates to eliminate most of the attack surface of the X.509 specification.

Projects who use safetlsa

Send a pull request if you'd like to be included.

  • TODO

Licence

safetlsa is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.

safetlsa is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with safetlsa. If not, see https://www.gnu.org/licenses/.

About

Generate TLS certificates from TLSA DNS records that are safe to add to a root CA trust store

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages